Palo Alto Networks Discloses More Details on Critical PAN-OS Flaw Under Attack
The Hacker News | Cyber Security,Hacking News
by
5h ago
Palo Alto Networks has shared more details of a critical security flaw impacting PAN-OS that has come under active exploitation in the wild by malicious actors. The company described the vulnerability, tracked as CVE-2024-3400 (CVSS score: 10.0), as "intricate" and a combination of two bugs in versions PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 of the software. "In ..read more
Visit website
Critical Update: CrushFTP Zero-Day Flaw Exploited in Targeted Attacks
The Hacker News | Cyber Security,Hacking News
by
5h ago
Users of the CrushFTP enterprise file transfer software are being urged to update to the latest version following the discovery of a security flaw that has come under targeted exploitation in the wild. "CrushFTP v11 versions below 11.1 have a vulnerability where users can escape their VFS and download system files," CrushFTP said in an advisory released Friday ..read more
Visit website
BlackTech Targets Tech, Research, and Gov Sectors New 'Deuterbear' Tool
The Hacker News | Cyber Security,Hacking News
by
14h ago
Technology, research, and government sectors in the Asia-Pacific region have been targeted by a threat actor called BlackTech as part of a recent cyber attack wave. The intrusions pave the way for an updated version of modular backdoor dubbed Waterbear as well as its enhanced successor referred to as Deuterbear. "Waterbear is known for its complexity, as it ..read more
Visit website
How Attackers Can Own a Business Without Touching the Endpoint
The Hacker News | Cyber Security,Hacking News
by
22h ago
Attackers are increasingly making use of “networkless” attack techniques targeting cloud apps and identities. Here’s how attackers can (and are) compromising organizations – without ever needing to touch the endpoint or conventional networked systems and services.  Before getting into the details of the attack techniques being used, let’s discuss why ..read more
Visit website
Akira Ransomware Gang Extorts $42 Million; Now Targets Linux Servers
The Hacker News | Cyber Security,Hacking News
by
22h ago
Threat actors behind the Akira ransomware group have extorted approximately $42 million in illicit proceeds after breaching the networks of more than 250 victims as of January 1, 2024. "Since March 2023, Akira ransomware has impacted a wide range of businesses and critical infrastructure entities in North America, Europe, and Australia," cybersecurity agencies from the Netherlands and the U.S ..read more
Visit website
Hackers Target Middle East Governments with Evasive "CR4T" Backdoor
The Hacker News | Cyber Security,Hacking News
by
1d ago
Government entities in the Middle East have been targeted as part of a previously undocumented campaign to deliver a new backdoor dubbed CR4T. Russian cybersecurity company Kaspersky said it discovered the activity in February 2024, with evidence suggesting that it may have been active since at least a year prior. The campaign has been codenamed  ..read more
Visit website
OfflRouter Malware Evades Detection in Ukraine for Almost a Decade
The Hacker News | Cyber Security,Hacking News
by
2d ago
Select Ukrainian government networks have remained infected with a malware called OfflRouter since 2015. Cisco Talos said its findings are based on an analysis of over 100 confidential documents that were infected with the VBA macro virus and uploaded to the VirusTotal malware scanning platform. "The documents contained VBA code to drop and run an executable with the name 'ctrlpanel.exe ..read more
Visit website
FIN7 Cybercrime Group Targeting U.S. Auto Industry with Carbanak Backdoor
The Hacker News | Cyber Security,Hacking News
by
2d ago
The infamous cybercrime syndicate known as FIN7 has been linked to a spear-phishing campaign targeting the U.S. automotive industry to deliver a known backdoor called Carbanak (aka Anunak). "FIN7 identified employees at the company who worked in the IT department and had higher levels of administrative rights," the BlackBerry research and intelligence team said in a new write-up. "They ..read more
Visit website
Recover from Ransomware in 5 Minutes—We will Teach You How!
The Hacker News | Cyber Security,Hacking News
by
2d ago
Super Low RPO with Continuous Data Protection:Dial Back to Just Seconds Before an Attack Zerto, a Hewlett Packard Enterprise company, can help you detect and recover from ransomware in near real-time. This solution leverages continuous data protection (CDP) to ensure all workloads have the lowest recovery point objective (RPO) possible. The most valuable thing about CDP is that it does not use ..read more
Visit website
How to Conduct Advanced Static Analysis in a Malware Sandbox
The Hacker News | Cyber Security,Hacking News
by
2d ago
Sandboxes are synonymous with dynamic malware analysis. They help to execute malicious files in a safe virtual environment and observe their behavior. However, they also offer plenty of value in terms of static analysis. See these five scenarios where a sandbox can prove to be a useful tool in your investigations. Detecting Threats in PDFs PDF files are frequently exploited by threat actors to ..read more
Visit website

Follow The Hacker News | Cyber Security,Hacking News on FeedSpot

Continue with Google
Continue with Apple
OR